GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Humanity hacker has minted an additional 100 million H tokens on the BSC chain, with $14 million worth awaiting sale

according to Lookonchain monitoring, the Humanity hacker has minted an additional 100 million H tokens on the BSC chain. The hacker has already obtained 18,510 ETH (worth $30.83 million) and 1,548 BNB (worth $924,000) by selling H tokens. The hacker currently still holds 111.36 million H tokens (worth $14 million) for sale. On-chain liquidity is now nearly depleted.

A newly created wallet, suspected to belong to Framework Ventures, has received 62.68 million H tokens from BitGo, worth $7.65 million.

according to monitoring by Onchain Lens, despite the hack of Humanity Protocol, a newly created wallet has received 62.68 million H tokens from BitGo, worth $7.65 million. The wallet is suspected to belong to VC Framework Ventures, though this has not yet been confirmed.

ZachXBT: Humanity Theft Incident May Have Been Staged; Private Key Leak Claim Is Just an Excuse for the Project Team to Evade Responsibility

Odaily reports: In response to the "Humanity theft incident," on-chain detective ZachXBT has released a new post stating that this "incident" was very likely a staged event. He fundamentally does not believe the team's corresponding explanation, which he sees as nothing more than an excuse fabricated by those with ill intentions to escape blame.According to earlier news, ZachXBT stated that it has not been confirmed whether the Humanity theft was a security attack or a malicious sell-off by the project team. The sell-off of the H token originated from a DEX rather than a CEX.

ZachXBT: Humanity Breach Not Yet Confirmed as Security Attack or Project Team Malicious Dump; H Token Sell-Off Came from DEX Rather Than CEX

in response to the "Humanity hack of over $31 million," on-chain detective ZachXBT stated, "It is uncertain whether this was a hacker's theft or a malicious act by the project team. Looking at the chart, given the concentration of supply, the H team was likely working with an active market maker. However, all H tokens were dumped on a decentralized exchange (on-chain), not on a centralized exchange."

Hackers continue to dump H tokens, with on-chain price dropping to $0.003, a 20x difference from Binance perpetual contract price

according to on-chain analyst Ember CN's monitoring, hackers are continuing to dump H tokens on-chain, with the on-chain price dropping to $0.003. The current Binance perpetual contract price stands at $0.06, a 20x difference from the on-chain price.

SlowMist Yu Xian: The Asterix attack resembles the Flooring Protocol’s approach.

SlowMist founder Yu Xian tweeted that, after preliminary analysis, the Asterix attack employed a method similar to yesterday’s Flooring Protocol incident. The underlying protocols involved are DN404 and BT404, respectively. The issue relates to integer overflow and reuse caused by high-value NFT ID bit-shift operations, suggesting the attacker may be searching for similar vulnerabilities.

Humanity Protocol Attacked, Losses Exceed $31 Million

According to Specter (@SpecterAnalyst), Humanity Protocol has been hacked, with losses exceeding $31 million. Funds are still being transferred, and the attacker is converting H into ETH.

Humanity Protocol associated address fund outflow continues, with losses exceeding $31 million

: According to Onchain Lens monitoring, Humanity Protocol has suffered a hacker attack, with losses exceeding $31 million. The fund outflow is ongoing, as the hacker is converting H tokens into ETH.

Arthur Hayes: Rising Oil Prices, AI-Related IPOs, and Trump's Anti-AI Rhetoric Could Pop the AI Bubble and Drag Down the Crypto Market

Odaily News, June 9th — BitMEX co-founder Arthur Hayes stated in his latest article "Reality Test" that if oil prices continue to rise due to the US-Iran conflict, it could trigger a collapse of the AI stock bubble and drag the entire crypto market down.Hayes said that if traffic restrictions in the Strait of Hormuz persist deep into the second quarter, spot prices for hydrocarbons and other key commodities could rise in the third quarter. If oil prices continue to climb and inflationary pressures impact the US midterm elections, Trump might pivot to a tough stance targeting data center construction, AI regulation, and taxation. Hayes believes the market could anticipate Trump limiting AI capital expenditure and taxing AI companies, thereby triggering the burst of the AI stock bubble.Hayes also noted that since November 2022, the scale of AI-related debt issuance has been approximately $1.5 trillion, and US M2 has increased by roughly the same amount during the same period. He believes the three factors that could pop the AI bubble include rising energy costs, the market's inability to absorb three major AI-related IPOs — namely SpaceX, Anthropic, and OpenAI — and Trump's shift to opposing AI. In terms of portfolio, Hayes stated that Maelstrom's stock portfolio holds significant positions in US-listed energy producers; he has sold AI-related stocks and offloaded non-core crypto assets, having dumped HYPE, NEAR, and WLD last week, as well as selling ZEC due to the Orchard Pool vulnerability. He still holds Bitcoin and ETH and will execute tactical short trades via derivatives.

Wallet Losses Exceed $19 Million, Humanity Protocol-Associated Wallet Suspected of Being Attacked

Wallets associated with or interacted with Humanity Protocol are being compromised. Currently, over 17 wallets holding H tokens have been stolen, with total losses exceeding $19 million. The cause of the theft remains unclear, but the attack pattern suggests that the affected wallets may share a common risk exposure related to Humanity Protocol.

Bitcoin Carjacking Accomplice Pleads Guilty, Faces Up to 20 Years in Prison

the US Department of Justice stated Saif Faiq has pleaded guilty to conspiracy charges in a Bitcoin-related kidnapping and extortion case, facing a maximum of 20 years in prison, with sentencing scheduled for August 28.The case occurred in 2024. Faiq and his brother Adam Iza were accused of plotting to kidnap the parents of a crypto millionaire, recruiting six men from Florida to carry out the operation in Connecticut. The suspects carjacked the victims' Lamborghini Urus in broad daylight, assaulting them and briefly holding them captive.The victims were Sushil and Radhika Chetal, whose son Veer Chetal was previously involved in a social engineering fraud case, stealing approximately 4,100 Bitcoins, and has already pleaded guilty to the theft. Faiq and his brother have both acknowledged conspiring to interfere with commercial activities through robbery.

Aave Founder Calls Protocol "Resilient" Despite $8.45 Billion Deposit Run Exposing Risks

in April this year, KelpDAO's LayerZero bridge was exploited in a $292 million vulnerability attack, triggering an $8.45 billion deposit run on Aave within 48 hours, marking the largest capital outflow event in decentralized finance (DeFi) history. Aave founder Stani Kulechov stated that the design of Aave V3 withstood the market test, demonstrating the network's "resilience." However, independent data indicates that Aave's survival primarily relied on $300 million in emergency rescue, including a 25,000 ETH guarantee from the Aave DAO and a personal injection of 5,000 ETH (approximately $8.4 million) by Kulechov.Kulechov attributed the vulnerability to third-party infrastructure rather than core smart contracts. However, analysts pointed out that this incident exposed deficiencies in Aave's risk architecture and insurance mechanisms, leading the platform to incur significant bad debt (approximately $123.7 million in wETH). To prevent future bridge failures from triggering systemic bank runs, Aave V4 will adopt a modular "hub-and-spoke" architecture, enabling local risk auto-adjustment and collateral freezing. (CoinDesk)

InfoHawk Secures $2.25 Million Pre-Seed Funding Led by Moonshots Capital

Odaily AI-driven anti-fraud infrastructure provider InfoHawk has announced the completion of a $2.25 million Pre-Seed funding round, led by Moonshots Capital, with participation from former U.S. Federal Trade Commission Chairman Jon Leibowitz, AppNexus founder Brian O'Kelley, former Meta advertising executive Rob Goldman, GitHub CTO Vlad Fedorov, and others. The new funds will be used to support the company's application of AI content recognition and deep infrastructure analysis technology to help enterprises detect, analyze, and combat large-scale online fraud, phishing sites, brand impersonation, and Deepfake attacks. (PRNewswire)

Bitget Chief Legal Officer Issues Open Letter, Helped Users Recover Over $32.3 Million in Fraud-Linked Funds Last Year

Bitget Chief Legal Officer Hon Ng issued an open letter today, announcing the official launch of Bitget’s 2026 Global Anti-Fraud Month campaign under the theme “More Assets, Stronger Protection.” In the letter, Hon Ng noted that as the platform expands from crypto assets to a multi-asset ecosystem, users are facing increasingly complex cybersecurity threats while enjoying broader market access. He emphasized: The multi-asset era means greater responsibility. User protection is not a one-time project but the collective result of continuous risk monitoring, rapid response, security education, and industry collaboration.The open letter also disclosed Bitget’s security and anti-fraud achievements for 2025. Data shows that Bitget intercepted over 150 million malicious attack requests throughout the year, identified more than 13,000 high-risk malicious IP addresses, handled 18,135 user protection cases, and assisted users in recovering approximately $32.3 million in funds related to security incidents and fraudulent activities. Additionally, Bitget’s security system achieved over 2.8 billion risk interceptions through custom protection rules, repelled more than 1.5 billion DDoS attack attempts, and introduced machine learning-based behavioral analysis capabilities to further identify suspicious activities and potential risks.

Polymarket launches "Zcash Orchard Privacy Pool Confirmed Vulnerable Exploit"

Odaily Seer monitoring shows that Polymarket has launched a new prediction event titled "Was Zcash's Orchard privacy pool confirmed to have been exploited?"On June 4, Zcash's core development team revealed that they had deployed an emergency network upgrade to fix a critical cryptographic vulnerability in the Orchard privacy pool. This flaw could have potentially allowed a malicious attacker to arbitrarily forge unlimited amounts of ZEC. Due to the vulnerability's characteristic that "it is impossible to cryptographically prove whether it was exploited in the past," independent support organization Shielded Labs subsequently proposed on June 5 to deploy a new privacy pool during the NU7 upgrade at the end of July. They also suggested implementing strict "Turnstile-accounting" audits for tokens exiting Orchard to investigate whether any forged tokens exist. According to the settlement rules for this prediction event, if before December 31, 2026, official sources or mainstream credible media confirm that the vulnerability was effectively exploited on the mainnet before being patched, the event will settle as YES.Odaily Seer continues to monitor prediction markets, seeing changes before pricing.

Yuga Labs Completes White-Hat Action on Flooring Protocol and Temporarily Takes Control of Multiple High-Value NFTs

Yuga Labs tweeted that it has completed a white-hat operation targeting a newly discovered vulnerability in the Flooring Protocol and is temporarily safeguarding the rescued assets, including 29 Bored Apes, 4 Mutant Apes, 1 BAKC, 2 CryptoPunks, 1 Azuki, 2 Elementals, 26 Captains, 1 Moonbird, and 2 Doodles.

Syscoin Discloses Preliminary Review of Cross-Chain Bridge Incident: Approximately 5 Billion SYS Tokens Abnormally Generated Due to Verification Issues

Syscoin released a preliminary post-mortem of the cross-chain bridge incident, stating that due to a verification issue in the bridging process, the attacker exploited an abnormal transaction proof validation to generate approximately 5 billion SYS tokens abnormally on the UTXO side via the affected bridging path.

ZachXBT Refutes Claims of Dubai Crypto Figure’s Detention, Says Individual Linked to Crypto Scams and Data Ransom

In response to Radha Stirling’s claims regarding alleged abuse of multiple Dubai-based cryptocurrency individuals in UAE detention facilities, on-chain investigator ZachXBT stated that the individuals referred to as “crypto entrepreneurs” are in fact threat actors suspected of involvement in high-impact social engineering cryptocurrency scams and data ransom operations; law enforcement authorities have seized $18.9 million in stolen funds.

New York Judge Pauses Ownership Lawsuit Over 39,000 Dormant Bitcoin Wallets, Hearing Set for July 14

New York Supreme Court Judge Kathy J. King has signed an order to pause proceedings in a lawsuit seeking ownership claims over 39,069 dormant bitcoin wallets, and has scheduled a hearing for July 14 regarding a key amicus curiae brief.The plaintiffs in the case are an anonymous individual referred to as "Noah Doe" and two shell companies, who are seeking to claim ownership of these wallets under the New York State Abandoned Property Law. Attorney Ian R. Cohen submitted an amicus curiae brief opposing the plaintiffs' claims. He argues that the Abandoned Property Law is intended for tangible items, whereas blockchain addresses are always visible to the world; if the original owner was unable to withdraw assets due to a security breach, this constitutes a passive loss of access rather than a voluntary abandonment. (The Block)

A rETH holder suffered a $4.5 million loss in a hacker attack, urgently transferring assets to secure $4.7 million

According to monitoring by Specter, 13 wallets belonging to a rETH holder were attacked on June 5, resulting in cumulative losses of approximately $4.5 million in assets. However, the victim detected the issue in time before the attacker could further transfer funds and successfully moved about $4.7 million in remaining assets. It is reported that these wallets had been inactive for years. The attacker has now begun laundering the stolen funds.